← Back

Foscam

foscam

65 CVEs • 84 products

Products (84)

Click to collapse
Toggle
C1 Firmware
c1_firmware
R2 Firmware
r2_firmware
R4 Firmware
r4_firmware
C2 Firmware
c2_firmware
Fi8919w
fi8919w
C1
c1
C1 Lite
c1_lite
C2
c2
Fi9800xe
fi9800xe
Fi9826p
fi9826p
Fi9828p
fi9828p
Fi9851p
fi9851p
Fi9853ep
fi9853ep
Fi9901ep
fi9901ep
Fi9903p
fi9903p
Fi9928p
fi9928p
R2
r2
C1 Webcam
c1_webcam
Fi9800p
fi9800p
Fi9821ep
fi9821ep
Fi9821p
fi9821p
Fi9831p
fi9831p
Fi9803p
fi9803p
Fi9815p
fi9815p
Fi9816p
fi9816p
R4
r4
Fi9961ep
fi9961ep
Fi9900ep
fi9900ep
Fi9900p
fi9900p
Fi9803ep
fi9803ep
Fi9821w
fi9821w
Fi9831w
fi9831w
Fi9826w
fi9826w
Fi9818w
fi9818w
Fi9805w
fi9805w
Fi9804w
fi9804w
Fi9804p
fi9804p
Fi9805e
fi9805e
Fi9805p
fi9805p
Fi9828w
fi9828w
Fi8620
fi8620
R2c
r2c

CVEs (65)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foscam
1C1 Firmware
Nov 21, 2024
Apr 17, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attacker who is in the same subnetwork of the camera or has remote administra...Show more
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attacker who is in the same subnetwork of the camera or has remote administrator access can fully compromise the device by performing a firmware recovery using a custom image.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can cause a buffer overflow.
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configurati...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configu...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configu...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configu...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command executionShow less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resul...Show more
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file res...Show more
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file res...Show more
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Webcam Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked...Show more
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overf...Show more
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overf...Show more
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the applic...Show more
An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an attacker to specify a file outside of a directory. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Indoor Hd Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less
1Foscam
1C1 Hd Indoor Camera Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting i...Show more
An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability.Show less
1Foscam
12C1
C1 LiteC2+9 more
May 13, 2026
Apr 10, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key f...Show more
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.Show less